Protocol//RUN
Protocol:RUN uses Google Play Games for sign-in, achievements and online Endless rankings. When connected, the game receives your Play Games player ID and gamer name, and sends achievement progress and scores to Google. Your full save file stays on your device; cloud saves are not enabled. I do not operate a separate account or game server.
Google's advertising and analytics components do collect data. The game shows ads through Google AdMob, which uses device and advertising identifiers to serve and measure them; and it sends gameplay measurements under an app instance ID to Google Firebase Analytics — how far runs go, which ads are offered and declined, what gets bought — so I can tell whether the game is any good and whether the ads are too intrusive. No separate crash-reporting service is installed; Google Play Games collects SDK diagnostics.
If you buy the Supporter unlock, Google Play handles the payment and I never see your payment details.
Everything below is the long version of those paragraphs.
Protocol:RUN is developed and published by Andy Marcus ("I", "me", "the developer"), an independent developer. For the purposes of the UK GDPR and EU GDPR, I am the data controller for the limited processing described in this policy.
Contact: protocolrun@andymarcus.com
I do not operate a separate account, leaderboard or game server. Google hosts Play Games sign-in, achievements and leaderboards. I also use a Firebase project for gameplay analytics, described in section 03. No separate crash-reporting service is installed; Google Play Games collects SDK diagnostics.
Your saved game — best scores, distances, credits, upgrades, cosmetics, contract
progress, daily streaks, settings and ghost replays — is written to a single file
in the app's private storage on your device (protocol_run.save). It
never leaves the device, it is not backed up to me, and I have no way to read it.
Uninstalling the game deletes it.
One distinction is worth stating plainly rather than leaving to be inferred: the save file stays on your phone, but some of the numbers in it — how far a run went, what it earned, what you spent credits on — are also sent as separate analytics events. The game does not add your Play Games player ID, gamer name or email to those Firebase events. Separately, it sends achievement progress and Endless leaderboard scores to Google Play Games when connected.
The local save also stores your Play Games player ID, achievement progress and pending score submissions so progress can be kept with the correct account and retried after an interrupted connection. Pending progress may be sent when you connect again.
The game includes Google's advertising, analytics, billing and Play Games components. Google operates these services under its own policies. I receive analytics reports through Firebase. The game also receives player identities, achievement progress and leaderboard results from Play Games to display them and keep progress in sync.
Protocol:RUN shows three kinds of ad: an in-run banner, rewarded ads you may choose to watch in exchange for continuing an Endless run or doubling the credits banked by an eligible Endless run or completed contract, and an occasional full-screen ad between runs. The guided tutorial is ad-free. Rewarded ads are always optional; declining one does not remove credits already earned. To serve and measure these, the Google Mobile Ads SDK may collect and process:
This is used to select ads, limit how often you see the same one, measure performance, and detect invalid or fraudulent traffic. Read Google's Privacy Policy and how Google uses data from apps that use its services.
AdMob and Google Play already tell me installs, sessions, revenue and retention with no code at all. Firebase Analytics is in the game for the questions those reports structurally cannot answer: how many runs a player actually takes, what share of players never reach the distance at which ads switch on, and how often a rewarded ad is offered and turned down. The last one is the reason it exists — an ad network can only ever see the offers that were accepted, and refusals are how I find out an offer is annoying rather than useful.
The Firebase SDK collects and processes:
BIND_GET_INSTALL_REFERRER_SERVICE permission in section 05 is for.
What it deliberately does not collect: no free-text of any kind, no contacts, no device identifiers beyond those above, no advertising ID (that is AdMob's, described above, and analytics does not read it), and no attempt to link any of this to a real identity. The game sets no user ID and no user properties — every event is a counter and a set of numbers.
Read Firebase's privacy and security documentation and the list of data Google Analytics for Firebase collects.
The game offers one optional purchase, the Supporter unlock, which removes banners and between-runs ads. Payment is handled entirely by Google Play. I receive only confirmation that a purchase for my product identifier succeeded. I never receive or store your name, card number, billing address or any other payment detail.
Play Games connects using your Google gaming profile and may sign you in automatically according to your Google settings. The game receives your Play Games player ID and gamer name, reads your achievement status, and sends achievement unlocks, progress counts and Endless scores to Google. This data is associated with your Play Games profile. It is used to award achievements, keep online records and show rankings.
Online rankings display gamer names, scores and ranks. Other players can see your game data according to your Play Games profile visibility settings. The game reads player IDs and gamer names from leaderboard results to display the board and identify your own entry. It does not request your Google email address, contacts or friends list. Google may display your avatar in its own profile and achievement screens.
Google also collects Play Games SDK analytics and diagnostics to maintain and improve the service. This is separate from the game's Firebase gameplay analytics and its ad consent controls. Play Games encrypts transmitted data using HTTPS. See Google's Play Games data disclosure and Google's Privacy Policy.
The game remains playable without a Play Games connection. Online rankings and syncing require a connection. The full save file, credits, upgrades, cosmetics and ghost replays are not uploaded as a cloud save.
The game is distributed through Google Play and relies on Google Play Services on your device. Google may process data in connection with app distribution, updates and integrity checks independently of this policy.
This summarizes the game's data use, including Play Games features introduced in version 1.5.0.
| Data type | Collected | Shared | Purpose |
|---|---|---|---|
| Advertising ID | Yes | Yes | Advertising, frequency capping, fraud prevention |
| App instance ID | Yes | No | Counting one player's runs as one player's; processed by Google Firebase on my behalf |
| Device & app info | Yes | Yes | Ad serving and measurement; analytics |
| Approximate location (from IP) | Yes | Yes | Regional ad targeting, analytics, legal compliance |
| Gameplay events — runs, distance, ads offered and declined, in-game spending | Yes | No | Measuring how the game is played and how intrusive its ads are |
| Purchase history | Yes | No | Delivering the Supporter unlock; held by Google Play |
| Play Games player ID and gamer name | Yes | Google; gamer name visible according to profile settings | Sign-in, account-specific progress and rankings |
| Achievements and leaderboard scores | Yes | Google; other players according to profile settings | Achievements and online rankings |
| Play Games SDK analytics & diagnostics | Yes | Processed by Google | SDK stability and service improvements; no separate crash-reporting service installed |
| Email, phone, address | No | No | — |
| Precise location | No | No | — |
| Contacts, photos, files, messages | No | No | — |
| Your save file | No | No | Not uploaded as a cloud save; analytics, achievement progress and scores are sent separately (section 02) |
Google Play's Data safety form uses broader categories and specific definitions of collection and sharing. The descriptions above explain what each service receives and what other players may see.
| Permission | Why |
|---|---|
| INTERNET | Requesting ads, sending analytics events, connecting to Play Games, syncing achievements and scores, and loading rankings. Gameplay remains available offline. |
| ACCESS_NETWORK_STATE | Checking whether a connection exists before requesting an ad. |
| AD_ID | Reading the advertising identifier, required by the ads SDK on Android 13 and above. Declared twice, in Google's namespace and Android's. |
| VIBRATE | Haptic feedback on near misses and impacts. Can be turned off in Settings. |
| WAKE_LOCK | Keeping the screen awake during a run. |
| ACCESS_ADSERVICES_AD_ID, _ATTRIBUTION, _TOPICS | Added by Google's ads SDK for Android's Privacy Sandbox advertising APIs. |
| BILLING | Offering the Supporter unlock through Google Play. |
| BIND_GET_INSTALL_REFERRER_SERVICE | Added by Firebase Analytics. Lets Google attribute an install to the listing or campaign it came from. |
| READ_BASIC_PHONE_STATE, FOREGROUND_SERVICE | Added by Google Play Services components; not used by the game directly. |
This list is read out of the merged manifest of the build being published, not
written from memory. The build also declares one permission of its own,
com.protocolrun.game.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION, which
is an Android support-library guard that stops other apps talking to the game's
internal broadcast receivers. It grants the game nothing.
Before any personalised ad is requested, the game shows a Google-certified consent message using Google's User Messaging Platform. You may refuse personalised ads; the game remains fully playable, and you will see non-personalised ads instead. You can reopen that choice at any time from Settings → Ad Privacy Choices inside the game.
That one answer governs analytics too. The game reads your consent in exactly one place and hands the same result to both Google components, so refusing leaves analytics collection switched off for the session as well. This is deliberate: a build where the ads believe you refused and the analytics believe you agreed is a build with a compliance problem, so there is only ever one answer to disagree about. If the app cannot establish your consent status at all, both stay off rather than defaulting on.
Being straight about the gap: outside the consent regions above, analytics collection is on by default and the game has no in-app switch to turn it off. The device-level controls in this section stop ad personalisation and reset the identifiers, but they do not stop the gameplay events in section 03 being sent. If you would rather they were not, write to me — that is a fair thing to ask for and the reason it is stated here rather than left to be discovered.
Where the UK or EU GDPR applies:
Play Games data is associated with your gaming identity. Your device keeps the player ID and local progress until the app's data is cleared or removed. Google retains online achievements and scores under its own policies and deletion controls; uninstalling the game does not remove that data from Google.
The analytics events in section 03 sit in my Firebase project under a retention window set in the Firebase console — currently 14 months for user-level data, after which Google deletes it automatically. Aggregate reports built from it may persist longer, in a form that describes players in general and no player in particular. Other Google-held data — ad serving data, purchase records and Play Games data — is retained under Google's own schedules, described in its privacy policy.
Because those events carry a randomly generated app instance ID and nothing else, I cannot look up "your" data, which is also why I cannot delete it on request: there is nothing to match a request against. Clearing the app's data severs the identifier immediately, and the retention window above disposes of what came before.
Google operates globally and may process data outside your country, including in the United States, relying on transfer mechanisms such as the EU Standard Contractual Clauses.
Depending on where you live, you may have rights to access, correct, delete or port your personal data, to object to or restrict processing, and to withdraw consent. Withdrawing consent is the one you can exercise yourself in seconds, from Settings → Ad Privacy Choices, with the effects on ads and Firebase gameplay analytics described in section 06. Play Games has separate account, visibility and deletion controls; Ad Privacy Choices does not disconnect it.
For the rest: most of the data described here is held by Google rather than by me, so requests are usually best made to Google directly. The analytics data in my own Firebase project is pseudonymous, as section 08 explains, which limits what an access or deletion request can be matched to — but write to me and I will do what can be done and tell you plainly what cannot.
If you are in the EEA or UK you may also complain to your national data protection authority. In the UK that is the Information Commissioner's Office.
If you are a California resident: I do not sell or share personal information as those terms are defined by the CCPA/CPRA. Ad personalisation may qualify as "sharing" for cross-context behavioural advertising, which you can turn off using the device controls in section 06.
Protocol:RUN is rated for players aged 13 and over and is not directed to children. It is not enrolled in Google Play's Designed for Families programme. I do not knowingly collect personal information from children. If you believe a child has provided information through this app, contact me and I will act on it.
If this policy changes, the date at the top of the page changes with it. Material changes — a new third party, or a new category of data — will be noted in the app's release notes as well. This policy describes how data is handled; it does not replace any consent Google or the game requests.
Questions, requests or corrections: protocolrun@andymarcus.com